CVE-2006-3426
N/A
N/A
Summary
Directory traversal vulnerability in (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1 and (b) Novell ZENworks 6.2 SR1 and earlier allows remote attackers to overwrite arbitrary files and directories via a .. (dot dot) sequence in the (1) action, (2) agentid, or (3) index parameters to dagent/nwupload.asp, which are used as pathname components.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html
- http://www.securityfocus.com/bid/18732
- http://www.securityfocus.com/archive/1/438710/100/0/threaded
- http://secunia.com/advisories/20876
- http://secunia.com/advisories/20878
- http://securityreason.com/securityalert/1200
- http://www.vupen.com/english/advisories/2006/2596
- http://www.vupen.com/english/advisories/2006/2595
- http://securitytracker.com/id?1016405
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047495.html
- http://www.securityfocus.com/bid/18732
- http://www.securityfocus.com/archive/1/438710/100/0/threaded
- http://secunia.com/advisories/20876
- http://secunia.com/advisories/20878
- http://securityreason.com/securityalert/1200
- http://www.vupen.com/english/advisories/2006/2596
- http://www.vupen.com/english/advisories/2006/2595
- http://securitytracker.com/id?1016405
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.